← Home

@sap-ux/deploy-config-sub-generator

Main generator for configuring ABAP or Cloud Foundry deployment configuration

51
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tqueckkranthie.sapsap_extncrepossap-ospo-admindevinea

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@sap-ux/store AI (phantom-deps): SAP-scoped dep in a monorepo; may be used transitively or indirectly — stable false positive. ai
phantom-deps phantom-dep:@sap-ux/btp-utils AI (phantom-deps): SAP-scoped dep in a monorepo; may be used transitively or indirectly — stable false positive. ai

Versions (showing 51 of 263)

View all versions
Version Deps Published
1.0.51 15 / 20
1.0.49 15 / 20
1.0.48 15 / 20
1.0.47 15 / 20
1.0.46 15 / 20
1.0.45 15 / 20
1.0.44 15 / 20
1.0.43 15 / 20
1.0.42 15 / 20
1.0.41 15 / 20
1.0.40 15 / 20
1.0.39 15 / 20
0.5.158 15 / 19
0.5.157 15 / 19
0.5.156 15 / 19
0.5.155 15 / 19
0.5.153 15 / 19
0.5.152 15 / 19
0.5.151 15 / 19
0.5.150 15 / 19
0.5.149 15 / 19
0.5.129 15 / 19
0.5.128 15 / 19
0.5.107 15 / 19
0.5.106 15 / 19
0.5.104 15 / 19
0.5.103 15 / 19
0.5.102 15 / 19
0.5.101 15 / 19
0.5.100 15 / 19
0.5.99 15 / 19
0.5.98 15 / 19
0.5.97 15 / 19
0.5.96 15 / 19
0.5.95 15 / 19
0.5.94 15 / 19
0.5.93 15 / 19
0.5.92 15 / 19
0.5.91 15 / 19
0.5.90 15 / 19
0.5.89 15 / 19
0.5.87 15 / 19
0.5.86 15 / 19
0.5.84 15 / 19
0.5.83 15 / 19
0.5.82 15 / 19
0.5.81 15 / 19
0.5.80 15 / 19
0.5.78 15 / 19
0.5.77 15 / 19
0.5.76 15 / 19

v1.0.51

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.49

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.48

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.39

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: devinea → GitHub Actions (on 2026-07-08, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (devinea) on 2026-07-08, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.